GuidesContact
Guides

Why scammers can send email as your business

CloudBuilder AI · 1 min read

Email has a strange default: unless your domain says otherwise, anyone can send mail that appears to come from it. Two free settings prevent this, and a large share of the small business domains we reviewed were missing at least one.

The two settings, in plain terms

SPF is a public list of the servers allowed to send email as your domain. DMARC is the policy that tells mail providers what to do when a message fails that test: deliver it anyway, quarantine it, or reject it. Without SPF, nothing declares who may send as you. Without DMARC, even a caught fake may still be delivered.

Why a small business is worth impersonating

Your name is trusted by exactly the people a scammer wants: your customers. An invoice that appears to come from your accountant, your salon, your clinic, gets opened and acted on. The scam defrauds your customers, and the reputation damage falls on your business.

What fixing it involves

Adding two DNS records with the right values for your actual email setup. It takes knowledge rather than time, wrong values can affect your own legitimate mail, which is why our $40 tune-up does it for you.

Related

Common questions

Will this stop all spoofing?
It makes sending as your exact domain fail authentication, which mail providers act on. Lookalike domains are a different trick it can't stop, but you close the most convincing version.
Could these settings break my own email?
Set wrongly, yes, which is exactly why we verify how your mail is actually sent before writing the records.